CVE-2024-35631: WordPress FV Flowplayer Video Player plugin <= 7.5.45.7212 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35631?
CVE-2024-35631 is considered a critical vulnerability due to its potential for reflected Cross-site Scripting (XSS) attacks.
How do I fix CVE-2024-35631?
To fix CVE-2024-35631, update the FV Flowplayer Video Player to version 7.5.45.7213 or later.
What software is affected by CVE-2024-35631?
CVE-2024-35631 affects FV Flowplayer Video Player versions up to and including 7.5.45.7212.
What type of vulnerability is CVE-2024-35631?
CVE-2024-35631 represents an Improper Neutralization of Input During Web Page Generation, categorized as a Cross-site Scripting (XSS) vulnerability.
Can CVE-2024-35631 be exploited by an attacker?
Yes, an attacker can exploit CVE-2024-35631 to execute malicious scripts in the context of the victim's session.